darvax[.]casa
“Energen - Free Bootstrap 4 Template by Colorlib”
ملخص الأدلة
The domain darvax.casa has been identified as a generic phishing threat, currently taken offline after posing a risk to unsuspecting visitors. Its page title, 'Energen - Free Bootstrap 4 Template by Colorlib', suggests an attempt to appear legitimate, possibly as a lure for credential theft or malware distribution. The domain was registered through Sav.com LLC and created on April 21, 2026, a relatively recent date that aligns with many phishing campaigns. It resolves to the IP address 185.221.216.121 and appears on one security blocklist, indicating prior recognition as malicious. Notably, VirusTotal flagged this domain with 22 out of 95 vendors marking it as malicious, a strong indicator of its dangerous nature. AlienVault OTX also includes it in one threat intelligence pulse, further corroborating the threat. Although the domain is now offline, its short lifespan and registration details underscore the importance of vigilance. Users should avoid any links or emails referencing darvax.casa, as similar domains may reappear. PhishDestroy recommends monitoring for lookalike domains and educating users to verify website authenticity before entering credentials or downloading files.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | darvax.casa/ghty/alto1.html |
malware | Detects file containing Telegram Bot API |
| OpenDNS | darvax.casa |
phishing | Phishing Block |
| Hagezi Threat Feed | darvax.casa |
malicious | Sinkholed |
| DNS4EU | darvax.casa |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
حُدّدت ٧ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of darvax.casa · checked Apr 23, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب